2025 CVE Vulnerabilities

45,203 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-59110MEDIUM6.5Windu CMS is vulnerable to Cross-Site Request Forgery in user editing functionality. Implemented CSRF protection mechani...
CVE-2025-55179MEDIUM5.4Incomplete validation of rich response messages in WhatsApp for iOS prior to v2.25.23.73, WhatsApp Business for iOS v2.2...
CVE-2025-13349MEDIUM5.4A vulnerability has been found in SourceCodester Student Grades Management System 1.0. This issue affects some unknown p...
CVE-2025-13347HIGH8.8A flaw has been found in SourceCodester Train Station Ticketing System 1.0. This vulnerability affects unknown code of t...
CVE-2025-13346HIGH8.8A vulnerability was detected in SourceCodester Train Station Ticketing System 1.0. This affects an unknown part of the f...
CVE-2025-12545MEDIUM5.3The Pixel Manager for WooCommerce – Track Conversions and Analytics, Google Ads, TikTok and more plugin for WordPress is...
CVE-2025-12376MEDIUM6.4The Icon List Block – Add Icon-Based Lists with Custom Styles plugin for WordPress is vulnerable to Server-Side Request ...
CVE-2025-10158MEDIUM4.3A malicious client acting as the receiver of an rsync file transfer can trigger an out of bounds read of a heap based bu...
CVE-2025-6670HIGH8.8A Cross-Site Request Forgery (CSRF) vulnerability exists in multiple WSO2 products due to the use of the HTTP GET method...
CVE-2025-41350MEDIUM5.4Stored Cross-site Scripting (XSS)vylnerability type in WinPlus v24.11.27 byInformática del Este that consist of an store...
CVE-2025-41349MEDIUM5.4Stored Cross-site Scripting (XSS)vylnerability type in WinPlus v24.11.27 byInformática del Este that consist of an store...
CVE-2025-41348CRITICAL9.8SQL injection vulnerability in WinPlus v24.11.27 by Informática del Este. This vulnerability allows an attacker recover,...
CVE-2025-13345HIGH8.8A security vulnerability has been detected in SourceCodester Train Station Ticketing System 1.0. Affected by this issue ...
CVE-2025-13344CRITICAL9.8A weakness has been identified in SourceCodester Train Station Ticketing System 1.0. Affected by this vulnerability is a...
CVE-2025-13343MEDIUM5.4A security flaw has been discovered in SourceCodester Interview Management System 1.0. Affected is an unknown function o...
CVE-2025-41737HIGH7.5Due to webserver misconfiguration an unauthenticated remote attacker is able to read the source of php modules.
CVE-2025-41736HIGH8.8A low privileged remote attacker can upload a new or overwrite an existing python script by using a path traversal of th...
CVE-2025-41735HIGH8.8A low privileged remote attacker can upload any file to an arbitrary location due to missing file check resulting in rem...
CVE-2025-41734CRITICAL9.8An unauthenticated remote attacker can execute arbitrary php files and gain full access of the affected devices.
CVE-2025-41733CRITICAL9.8The commissioning wizard on the affected devices does not validate if the device is already initialized. An unauthentica...
CVE-2025-41347CRITICAL9.8Unlimited upload vulnerability for dangerous file types in WinPlus v24.11.27 from Informática del Este. This vulnerabili...
CVE-2025-11427MEDIUM5.8The WP Migrate Lite – WordPress Migration Made Easy plugin for WordPress is vulnerable to Blind Server-Side Request Forg...
CVE-2025-4212HIGH7.2The Checkout Files Upload for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via file upl...
CVE-2025-41346CRITICAL9.8Faulty authorization control in software WinPlus v24.11.27 by Informática del Este that allows another user to be impers...
CVE-2025-13196MEDIUM5.4The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Open Str...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now